P03- SOW (Draft).pdf

PDF 864 KB Posted

Attached to
Quark Publishing Platform Production System (License) Federal contract opportunity
Solicitation number
284784
Issued by
Department of Agriculture Under Secretary for Farm Production and Conservation

About this file

This statement of work outlines requirements for renewing Quark licenses and maintenance for the US Department of Agriculture Farm Production and Conservation Business Center. Key requirements include:

  • Renewing annual maintenance for the Quark Publishing Platform production system with 1000 named users, including the Quark server, subrenderers, and Quark Author web edition. Delivery date is September 30, 2023 for the base period through September 29, 2024 with two option periods.

  • The Quark system is used to author, edit, release and maintain Conservation Practice Documents for 34 Conservation Practice Standards and supporting documents on a 5-year revision schedule. It provides a quality assurance review workflow for national, state and area staff.

  • The contractor must comply with Section 508 accessibility, IPv6, FedRAMP moderate baseline requirements if a cloud solution is proposed, and USDA IT security policies. Pricing must be provided at the line item level within 10 days of award or activation.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

1 | P a g e

Statement of Work Quark License and Maintenance Renewal

Background

In 2018, the FPAC Business Center (FPAC-BC) was formed within the FPAC Mission Area to centralize operations with divisions for acquisition and procurement, budget, financial management, grants and agreements, human resources, information solutions, management services, performance accountability and risk, economics and policy analysis, environmental activities, appeals and litigation, customer experience, homeland security, and external affairs.

The FPAC-BC Information Solutions Division (ISD) realigned the information technology delivery functions from FSA, NRCS, and RMA to a single organization. The FPAC ISD primary customers include FSA headquarters and field employees, NRCS headquarters and field employees, RMA headquarters employees and approved insurance providers, and FPAC Business Center employees.

The Nationalizing Conservation Practice Standards Documents (CPD) Project, commissioned in 2012, is a multi-year development and implementation rollout effort. The three main components of this project are nationalizing Conservation Practice Documents (CPD), implementing a quality assurance process, and developing the Conservation Practice Documents-Document Management System (CPD-DMS).

Supplemental activities include the associated revisions to Handbook GM 450, Part 401, Subpart B, and to Chapter 1 of the (National Handbook of Conservation Practices (NHCP). Other tasks include revisions to the Electronic Field Office Guide (eFOTG) and development of the Conservation Practice Data Entry System (CPDES).

The Quark publishing platform manages and automates the creation, processing, and publishing of content.

The Quark authoring application is a web-based content creation tool, which together with the Quark publishing platform, allows for streamlining and automation of content generation and review/feedback loop involved in creating, previewing, publishing, and reusing content. Quark has been integrated in the EDM platform and has the following Quark footprint:

Quark Publishing Platform - Production System Quark Publishing Platform manages and automates the creation, processing, and publishing of content. The modules of Quark Publishing Platform work together to automatically enable the assembly of content for different audiences, and publication and media types creating an end-to-end publishing workflow that speeds time-to-market, improves customer satisfaction and lowers cost.

Quark Publishing Platform server connections Access to the Quark platform is controlled through server connections. These connections permit users to be part of the management and automation of the creation, processing and publishing of content, as described above, while the platform manages the audit and governance of their activities. 1000 connections are provided with the CLIENT base platform.

licensing, further connections are required above this.

Quark Author Named User License Quark Author is Web-based content creation software that, together with Quark Publishing Platform, enables the streamlining and automation of high-value customer communications, The intuitive online authoring experience means subject matter experts – wherever they are – can rapidly create, preview, publish and reuse content.

At the USDA, the Quark Publishing and Authoring Platform is being used to author, edit, release and maintain Conservation Practice Documents (CPD) such as Implementation Requirements, Operations & Maintenance (O&M), and Specifications documents. The platform also provides for the Quality assurance (QA) review process workflow involving the national, state and area staff, while allowing the capture of the Review Feedback and Response History. The 34 Conservation Practice Standards (CPS) and supporting

DRAFT

2 | P a g e

CPDs are worked on each year to maintain the 5-year revision schedule required by policy. When finalized, the standards are published to the NHCP, making them available for public use.

The Quark toolset is used by the National Practice Discipline leads and their teams, Quality assurance teams, State Conservation Engineers, State Engineering Staff, Area Engineering Staff, State Resource Conservationists and their staff, Centers staff.

Objectives FPAC will renew Quark licenses and maintenance as a base award and two option periods.

Delivery

• Electronic Delivery of Licenses: SM.FPAC.BC.SDT.LICENSEMANAGEMENT@USDA.GOV

Delivery Dates Base Period 09/30/2023 – 09/29/2024 Option Year One 09/30/2024 – 09/29/2025

Requirements:

Line Item Product QTY 1 Annual Maintenance Renewal for Quark Publishing Platform Production

System with 1000 Named Users, QXP Server & Subrenderers, Quark Author Web Edition. Managed Service 30 days.

1. Software Line-Item Pricing Deliverable In accordance with Office of Management and Budget Memorandum M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Information Technology: Software Licensing, USDA must maintain an inventory of its software licenses, including pricing data. The contractor shall provide line-item pricing data on all software licenses provided to USDA at award and/or during performance of the contract/order. The attachment entitled “Software Template Line- Item Pricing” must be completed and provided to the Contracting Officer’s Representative within 10 days of award, or within 10 days of activation for licenses provided after the award date. (See Deliverable Table below)

Deliverable Submitted to: Due Date:

Software Line Item Pricing Contracting Officer’s

Representative Within 10 Days of Award, or Within 10 Days of Software Activation for Licenses Provided After Award Date

Appendix A: Mandatory IT Contract Requirements

1.30. Compliance with Security IT Policies

Information systems and system services provided by the Contractor must comply with the current USDA IT security and privacy policies, specifically the 3500 – 3599 Cyber Security Department regulations - https://www.ocio.usda.gov/policy-directives-records-forms/directives-categories.

The Contractor is required to comply with current Federal regulations and guidance found in the Federal Information Security Modernization act of 2014 (FISMA); Privacy Act of 1974; E- Government Act of 2002, Section 208; National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) and the 800-Series Special Publications (SP), specifically 800-40, Guide to Enterprise Patch Management Technologies; Office of Management and Budget

3 | P a g e

(OMB) memoranda; USDA Information Security Program policies and other relevant Federal laws and regulations with which USDA must comply.

House Resolution 83-15 “Consolidated and Further Continuing Appropriations Act, 2015” requires that USDA demonstrate each project/investment is “being managed in accordance with applicable lifecycle management policies and guidance.” This mandates that USDA development projects are required to follow the Agency’s System Development Lifecycle (SDLC). All projects listed in Farm Service Agency Farm Programs IT plan for expenditure can expect to be audited for compliance.

Audits may occur at any time after the plan for expenditure is submitted to Congress.

The Contractor must protect information regarding security issues and associated documentation to limit the likelihood that vulnerabilities in operational client software are exposed. If new vulnerabilities are identified after the acceptance of COTS software, the vendor must review and remediate the vulnerabilities and present the results for Government approval within the timeframes documented in USDA IT security policies.

SECTION 508 – ACCESSIBILITY OF INFORMATION AND COMMUNICATIONS

TECHNOLOGY

This contract vehicle is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 749d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220). The Revised Section 508 Standards, which consist of 508 Chapters 1 and 2 (Appendix A), along with Chapters 3 through 7 (Appendix C), contain scoping and technical requirements for information and communication technology (ICT) to ensure accessibility and usability by individuals with disabilities. Compliance with these standards is mandatory for Federal agencies subject to Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C.

794d).

Each ICT product or service furnished under this contract shall comply with the Revised Section 508 ICT Accessibility Standards at a minimum, as specified in the contract. If any furnished product or service is determined to be noncompliant, the Contracting Officer will notify the Contractor in writing. The Contractor shall, without charge to the Government, remediate or replace the noncompliant products or services within a specified timeframe as determined by the Government in writing. If such remediation or replacement is not completed within the time specified, the Government shall have the following recourses:

1) Cancellation of the contract, delivery, task order, purchase, or line item without termination liabilities; or

2) In the case of custom ICT being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the noncompliant ICT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.

The contractor must ensure all noncompliant ICT products and services are provided pursuant to extensive market research and exhibit the highest level of compliance while satisfying the contract requirements.

For every ICT product or service accepted under this contract by the Government that does not comply with the Revised Section 508 Accessibility Standards, the contractor shall, at the discretion of the Government, remediate or upgrade the item with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date, whichever shall occur first.

SECTION 508 COMPLIANCE

Vendors, contractors, and their respective ICT products and services shall comply with the following standards, policies, and procedures. In the event of conflicts between the referenced documents and this contract vehicle, the contract vehicle shall take precedence.

1) Revised Section 508 ICT Accessibility Standards

2) Section 508 of the Rehabilitation Act as amended (29 U.S.C. 794d)

4 | P a g e

3) Federal Acquisition Regulation (FAR) Subpart 39.2

4) USDA Section 508 Departmental Regulation

Additionally, all contract deliverables are subject to these standards.

All ICT products and services, regardless of format, must conform to the applicable Section 508 standards to allow Federal employees and members of the public with disabilities equivalent access to and use of information and data provided to those without disabilities.

All contractors, sub-contractors, and consultants are responsible for preparing or posting content must comply with the applicable Section 508 accessibility standards and, where applicable, those set forth in the referenced policy or standards document. Remediation of any noncompliant ICT or materials as set forth in this contract vehicle shall be the responsibility of the contractor, sub-contractor, or consultant.

According to the Access Board’s Section 508 Scoping Requirements The following Section 508 provisions apply to the products and/or services identified in this contract vehicle:

• C202 Functional Performance Criteria: Where the requirements in Chapters 4 and 5 do not address one or more functions of telecommunications or customer premises equipment, the functions not addressed shall conform to the Functional Performance Criteria specified in Chapter 3.

• C203 Electronic Content: Electronic content that is integral to the use of telecommunications or customer premises equipment shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0.

• C204 Hardware: Where components of telecommunications equipment and customer premises equipment are hardware, and transmit information or have a user interface, those components shall conform to applicable requirements in Chapter 4.

• C205 Software: Where software is integral to the use of telecommunications functions of telecommunications equipment or customer premises equipment and has a user interface, such software shall conform to C205 and the applicable requirements in Chapter 5.

WCAG Conformance: User interface components, as well as the content of platforms and applications shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0.

• C206 Support Documentation and Services: Where support documentation and services and provided for telecommunications equipment and customer premises equipment, manufacturers shall ensure that such documentation and services conform to Chapter 6 and are made available upon request at no additional charge.

In addition, vendors and contractors shall comply with the standards, policies, and procedures below for all ICT pursuant to this contract:

• For Custom ICT Development Services, the vendor or contractor shall ensure the ICT fully conforms to the applicable Revised Section 508 standards prior to delivery and before final acceptance.

• For Installation, Configuration, and Integration Services, the vendor or contractor shall not install, configure, or integrate the equipment and software in a way that reduces the level of conformance with the applicable Revised Section 508 standards.

• For Maintenance, Upgrades, and Replacements, the vendor or contractor shall ensure maintenance upgrades, substitutions, and replacements do not reduce the original level of conformance with the applicable Revised Section 508 standards at the time of the contract award.

• Service Personnel are ensured by the vendor or contractor to possess the knowledge, skills, and ability necessary to address the applicable Revised Section 508 standards and shall provide supporting documentation upon request.

• When providing Hosting Services, the vendor or contractor shall not reduce the existing level of conformance of the electronic content with the applicable Revised Section 508 standards.

• When purchasing ICT where 1) Section 508 validation is not possible prior to award, 2) the ICT will be changed after the award, or 3) ICT will be hosted in a third-party environment, the vendor

5 | P a g e or contractor shall test and validate the ICT solution for conformance to the Revised Section 508 standards, in accordance with the required testing methods as defined by the agency.

• The vendor or contractor shall document and maintain information regarding the measures taken to ensure compliance with the applicable requirements. This documentation includes but is not limited to testing records, product demonstrations, and reported defects by end users and testers.

• Prior to acceptance, the vendor or contractor shall provide an Accessibility Conformance Report (ACR) for each ICT item that is developed, updated, and/or configured for the agency, and when product substitutions are offered. The ACR should be based on the latest version of the Voluntary Product Accessibility Template (VPAT) provided by the Information Technology Industry Council (ITI). To be considered for award, an ACR must be submitted for each ICT item, and must be completed according to the instructions provided by the ITI.

Note: A supplemental ACR may be required if the agency has additional or stricter accessibility requirements than what is outlined in the VPAT.

• Prior to acceptance, the agency reserves the right to require a full working demonstration of the completed ICT item to demonstrate conformance to the agency’s accessibility requirements in addition to independent testing to validate.

• In the case of non-compliance where the vendor or contractor claims its products and/or services satisfy the applicable Revised Section 508 standards specified in the contract vehicle, the contracting officer will promptly inform the vendor or contractor in writing of the non-compliance. The vendor or contractor shall, at no cost to the agency, repair or replace the non-compliant products or services within the period specified by the contracting officer.

All Information and Communications Technology (ICT) subject to the Revised Section 508 standards will be evaluated for Section 508 conformance and usability. The test must be administered by a Federal Section 508 Testing Center. All maintenance for ICT that requires upgrades, modifications, installations, repairs, and purchases shall adhere to the Revised Section 508 standards.

3.30. WCAG 2.0 Compliance

The software must comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this SOW, the SOW must take precedence.

Custom ICT Development Services When Vendor provides custom ICT development services pursuant to this contract, Vendor must ensure the ICT fully conforms to the applicable Revised 508 Standards prior to delivery and before final acceptance.

Installation, Configuration, and Integration Services When Vendor provides installation, configuration, or integration services for equipment and software pursuant to this contract, the offeror must not install, configure, or integrate the equipment and software in a way that reduces the level of conformance with the applicable Revised 508 standards.

Maintenance, Upgrades, and Replacements Vendor must ensure maintenance upgrades, substitutions, and replacements to equipment and software pursuant to this contract do not reduce the original level of conformance with the applicable Revised 508 standards at the time of the contract award.

Service Personnel Vendor must ensure the personnel providing the labor hours possess the knowledge, skills, and ability necessary to address the applicable Revised 508 standards defined in this contract and must provide supporting documentation upon request.

Hosting Services

6 | P a g e

When providing hosting services for electronic content provided by the agency, Vendor must not implement the hosting services in a manner that reduces the existing level of conformance of the electronic content with applicable Revised 508 standards. Throughout the life of the contract, the agency reserves the right to perform testing on a vendor or contractor’s hosted solution to verify conformance with this requirement.

Validation for ICT Items When purchasing ICT where 1) 508 validation is not possible prior to award, 2) when ICT will be changed after the award, or 3) ICT will be hosted in a third-party environment, Vendor must test and validate the ICT solution for conformance to the Revised 508 standards, in accordance with the requirement testing methods, as defined by the agency. Throughout the life of the contract, the agency reserves the right to perform testing to verify conformance with this requirement.

Documentation Vendor must maintain and retain full documentation of the measures taken to ensure compliance with the applicable requirements, including records of any testing or demonstrations conducted.

Conformance Reporting Prior to acceptance, Vendor must provide an Accessibility Conformance Report (ACR) for each ICT item that is developed, updated, configured for the agency, and when product substitutions are offered.

The ACR should be based on the latest version of the Voluntary Product Accessibility Template (VPAT) provided by the Information Technology Industry Council (ITI). To be considered for award, an ACR must be submitted for each ICT item, and must be completed according to the instructions provided by ITI.

When the contractor is required to perform testing to validate conformance to the agency’s accessibility requirements, Vendor must provide a Supplemental Accessibility Conformance Report (SAR) that contains the following information:

• Accessibility test results based on the required test methods.

• Documentation of features provided to help achieve accessibility and usability for people with disabilities.

• Documentation of core functions that cannot be accessed by persons with disabilities.

• Documentation on how to configure and install the ICT item to support accessibility.

• When an ICT item is an authoring tool that generates content (including documents, reports, videos, multimedia productions, web content, etc.)., provide information on how the ICT item enables the creation of accessible electronic content that conforms to the Revised 508 Standards, including the range of accessible user interface elements the tool can create.

• Before final acceptance, the contractor must provide a fully working demonstration of the completed ICT Item to demonstrate conformance to the agency's accessibility requirements. The demonstration must expose where such conformance is and is not achieved.

Before acceptance, the agency reserves the right to perform independent testing to validate that the ICT solution provided by the contractor conforms to the applicable Revised 508 standards.

Non-Compliance Before final acceptance of any ICT item, including updates and replacements, if Vendor claims its products or services satisfy the applicable Revised 508 standards specified in the contract vehicle, and the contracting officer determines that any furnished ICT item is not in compliance with such

7 | P a g e requirements, the contracting officer will promptly inform Vendor in writing of the non-compliance.

Vendor must, at no cost to the agency, repair or replace the non-compliant products or services within the period specified by the contracting officer.

COMPLIANCE WITH INTERNET PROTOCOL VERSION 6 (IPV6) IN ACQUIRING

INFORMATION TECHNOLOGY

Any system, hardware, software, firmware or networked component (voice, video or data) developed, procured or acquired in support or performance of this contract must be capable of transmitting, receiving, processing, forwarding and storing digital information across system boundaries utilizing system packets that are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 500-267) and corresponding declarations of conformance defined in the USGv6 Test Program. In addition, this system must maintain interoperability with IPv4 systems and provide at least the same level of performance and reliability capabilities of IPv4 products:

• Specifically, any new IP product or system developed, acquired, or produced must:

o Interoperate with both IPv6 and IPv4 systems and products, and o Have available contractor/vendor IPv6 technical support for development and implementation and fielded product management.

• As IPv6 evolves, the Contractor commits to upgrading or providing an appropriate migration path for each item developed, delivered or utilized at no additional cost to the Government.

• The Contractor must provide technical support for both IPv4 and IPv6.

• Any system or software must be able to operate on networks supporting IPv4, IPv6 or one that supports both.

• Any product whose non-compliance is discovered and made known to the Contractor within one year after acceptance must be upgraded, modified or replaced to bring it into compliance at no additional cost to the Government.

FEDRAMP CERTIFICATION

5.30. If a Cloud solution is considered:

5.30.1. A cloud-hosted application for the Federal Government should be managed at the FedRAMP Moderate Baseline or higher, and it should include details on:

5.30.1.1. Number of users of the application.

5.30.1.2. Handling and implementing change requests.

5.30.1.3. Patching and completing security updates.

5.30.1.4. Meeting service level agreements. Offeror should include what service levels (such as availability) they were required to meet and if they were unable to meet them.

5.30.1.5. Handling and correcting trouble tickets, incidents, and problem.

5.30.2. Transitioning data and services to a cloud-hosted Software-as-a Service for a Federal Government at FedRAMP Moderate Baseline or higher.

5.30.3. Meeting and maintaining cybersecurity authorizations and accreditations at FedRAMP Moderate baseline or higher.

Appendix A: Mandatory IT Contract Requirements

8 | P a g e

5.31. Compliance with Security IT Policies

Information systems and system services provided by the Contractor must comply with the current USDA IT security and privacy policies, specifically the 3500 – 3599 Cyber Security Department regulations - https://www.ocio.usda.gov/policy-directives-records-forms/directives-categories.

The Contractor is required to comply with current Federal regulations and guidance found in the Federal Information Security Modernization act of 2014 (FISMA); Privacy Act of 1974; E- Government Act of 2002, Section 208; National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) and the 800-Series Special Publications (SP), specifically 800-40, Guide to Enterprise Patch Management Technologies; Office of Management and Budget (OMB) memoranda; USDA Information Security Program policies and other relevant Federal laws and regulations with which USDA must comply.

House Resolution 83-15 “Consolidated and Further Continuing Appropriations Act, 2015” requires that USDA demonstrate each project/investment is “being managed in accordance with applicable lifecycle management policies and guidance.” This mandates that USDA development projects are required to follow the Agency’s System Development Lifecycle (SDLC). All projects listed in Farm Service Agency Farm Programs IT plan for expenditure can expect to be audited for compliance.

Audits may occur at any time after the plan for expenditure is submitted to Congress.

The Contractor must protect information regarding security issues and associated documentation to limit the likelihood that vulnerabilities in operational client software are exposed. If new vulnerabilities are identified after the acceptance of COTS software, the vendor must review and remediate the vulnerabilities and present the results for Government approval within the timeframes documented in USDA IT security policies.

COMPLIANCE WITH INTERNET PROTOCOL VERSION 6 (IPV6) IN ACQUIRING

INFORMATION TECHNOLOGY

Any system, hardware, software, firmware or networked component (voice, video or data) developed, procured or acquired in support or performance of this contract must be capable of transmitting, receiving, processing, forwarding and storing digital information across system boundaries utilizing system packets that are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 500-267) and corresponding declarations of conformance defined in the USGv6 Test Program. In addition, this system must maintain interoperability with IPv4 systems and provide at least the same level of performance and reliability capabilities of IPv4 products:

• Specifically, any new IP product or system developed, acquired, or produced must:

o Interoperate with both IPv6 and IPv4 systems and products, and o Have available contractor/vendor IPv6 technical support for development and implementation and fielded product management.

• As IPv6 evolves, the Contractor commits to upgrading or providing an appropriate migration path for each item developed, delivered, or utilized at no additional cost to the Government.

• The Contractor must provide technical support for both IPv4 and IPv6.

• Any system or software must be able to operate on networks supporting IPv4, IPv6 or one that supports both.

• Any product whose non-compliance is discovered and made known to the Contractor within one year after acceptance must be upgraded, modified, or replaced to bring it into compliance at no additional cost to the Government.

1.30. Compliance with Security IT Policies
2.0 Section 508 – Accessibility of Information and Communications Technology
3.0 Section 508 Compliance
3.30. WCAG 2.0 Compliance
4.0 Compliance with Internet Protocol version 6 (IPv6) in Acquiring Information Technology
5.0 FEDRAMP CERTIFICATION
5.30. If a Cloud solution is considered:
5.30.1. A cloud-hosted application for the Federal Government should be managed at the FedRAMP Moderate Baseline or higher, and it should include details on:
5.30.1.1. Number of users of the application.
5.30.1.2. Handling and implementing change requests.
5.30.1.3. Patching and completing security updates.
5.30.1.4. Meeting service level agreements. Offeror should include what service levels (such as availability) they were required to meet and if they were unable to meet them.
5.30.1.5. Handling and correcting trouble tickets, incidents, and problem.
5.30.2. Transitioning data and services to a cloud-hosted Software-as-a Service for a Federal Government at FedRAMP Moderate Baseline or higher.
5.30.3. Meeting and maintaining cybersecurity authorizations and accreditations at FedRAMP Moderate baseline or higher.

5.31. Compliance with Security IT Policies

6.0 Compliance with Internet Protocol version 6 (IPv6) in Acquiring Information Technology

File details come from the government source that posted it. Updated .